Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 144

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Movie: Sorry, Baby
Book: The Unaccountability Machine: Why Big Systems Make Terrible Decisions
communication process tools/diagrams/explanations
Help me find a pro bono illustrator for my childrens book for Gaza
Answered: [New Premium Plugin] Q2A Avatar Cropper (square image 1:1)
Stocks making the biggest moves midday: Hershey, Chemours, Fair Isaac, Sunrun & more
Tech founders call on Sequoia Capital to denounce VC Shaun Maguire's Mamdani comments
'Big beautiful bill' may help some seniors on Social Security. But it doesn't eliminate taxes on benefits
TSA to end shoe removal policy at some airport security checkpoints, government source says
Here are the 15 busiest airports in the world